Bugtraq mailing list archives
Re: MS to stop allowing passwords in URLs
From: Paul Smith <paullocal () pscs co uk>
Date: Tue, 03 Feb 2004 16:52:34 +0000
At 22:54 28/01/2004, McAllister, Andrew wrote:
I just read that Microsoft will stop allowing IDs and passwords to be embedded in URLs used by Internet Explorer. So you will no longer be able to use a URL like https://user:password () www somehost com/ See http://support.microsoft.com/default.aspx?scid=kb;en-us;834489
Anyone have any comments regarding legitimate uses of this syntax and Microsoft removing it from their browser? (and presumably the OS since the browser IS the OS).
Personally, I think it's a reasonable step - these spoofed URLs are a big problem for many people.
You can disable the functionality in IE if you wish (the above link has details)
I think I'd prefer it if you could override it on a site by site basis (eg using the 'trusted sites' functions, or by having the username:password@url in your IE 'favourites')
(Although, having said that, having spammers use http://username@url is quite a good trigger to put in email anti-spam rules, as I've never seen anyone use that format in an email link legitimately..)
Paul VPOP3 - Internet Email Server/Gateway support () pscs co uk http://www.pscs.co.uk/
Current thread:
- Re: MS to stop allowing passwords in URLs, (continued)
- Re: MS to stop allowing passwords in URLs David B Harris (Feb 03)
- Re: MS to stop allowing passwords in URLs Östlund (Feb 04)
- Re: MS to stop allowing passwords in URLs Nick FitzGerald (Feb 06)
- Message not available
- Re: MS to stop allowing passwords in URLs Vinny Abello (Feb 03)
- Re: MS to stop allowing passwords in URLs Ansgar -59cobalt- Wiechers (Feb 03)
- RE: MS to stop allowing passwords in URLs Andrew Harwood (Feb 03)
- Re: MS to stop allowing passwords in URLs 3APA3A (Feb 03)
- Re: MS to stop allowing passwords in URLs Dave McCormick (Feb 03)
- Re: MS to stop allowing passwords in URLs Nick FitzGerald (Feb 03)
- Re: MS to stop allowing passwords in URLs Sam Schinke (Feb 03)
- Message not available
- Re: MS to stop allowing passwords in URLs Paul Smith (Feb 03)
- RE: MS to stop allowing passwords in URLs Richard M. Smith (Feb 03)
- RE: MS to stop allowing passwords in URLs Francis Favorini (Feb 03)
- RE: MS to stop allowing passwords in URLs Thor Larholm (Feb 03)
- Re: MS to stop allowing passwords in URLs Sam Schinke (Feb 05)
- RE: MS to stop allowing passwords in URLs NESTING, DAVID M (SBCSI) (Feb 05)